Linux kernel -stable discussions
 help / color / mirror / Atom feed
From: Coiby Xu <coxu@redhat.com>
To: gregkh@linuxfoundation.org
Cc: bhe@redhat.com, msuchanek@suse.de, will@kernel.org,
	zohar@linux.ibm.com, stable@vger.kernel.org
Subject: Re: FAILED: patch "[PATCH] arm64: kexec_file: use more system keyrings to verify kernel" failed to apply to 5.10-stable tree
Date: Thu, 18 Aug 2022 12:15:36 +0800	[thread overview]
Message-ID: <20220818041536.5urxrunzmdawkdh7@Rk> (raw)
In-Reply-To: <166057758686253@kroah.com>

Hi Greg,


This patch depends on three prerequisites. This full list of commit ids
should be backported is shown below,

1. 65d9a9a60fd7 ("kexec_file: drop weak attribute from functions")
2. 689a71493bd2 ("kexec: clean up arch_kexec_kernel_verify_sig")
3. c903dae8941d ("kexec, KEYS: make the code in bzImage64_verify_sig generic")
4. 0d519cadf751 ("arm64: kexec_file: use more system keyrings to verify kernel image signature")

$ git checkout -b arm_key_5.10.y stable/linux-5.10.y
Updating files: 100% (33255/33255), done.
branch 'arm_key_5.10.y' set up to track 'stable/linux-5.10.y'.
Switched to a new branch 'arm_key_5.10.y'
$ git cherry-pick 65d9a9a60fd7 689a71493bd2 c903dae8941d 0d519cadf751
Auto-merging arch/arm64/include/asm/kexec.h
Auto-merging arch/powerpc/include/asm/kexec.h
Auto-merging arch/s390/include/asm/kexec.h
Auto-merging arch/x86/include/asm/kexec.h
Auto-merging include/linux/kexec.h
Auto-merging kernel/kexec_file.c
[arm_key_5.10.y 624dfcf3b8de] kexec_file: drop weak attribute from functions
  Author: Naveen N. Rao <naveen.n.rao@linux.vnet.ibm.com>
  Date: Fri Jul 1 13:04:04 2022 +0530
  6 files changed, 61 insertions(+), 40 deletions(-)
Auto-merging include/linux/kexec.h
Auto-merging kernel/kexec_file.c
[arm_key_5.10.y da8cfa52682e] kexec: clean up arch_kexec_kernel_verify_sig
  Date: Thu Jul 14 21:40:24 2022 +0800
  2 files changed, 13 insertions(+), 25 deletions(-)
Auto-merging arch/x86/kernel/kexec-bzimage64.c
Auto-merging include/linux/kexec.h
Auto-merging kernel/kexec_file.c
[arm_key_5.10.y 0bb032082ce6] kexec, KEYS: make the code in bzImage64_verify_sig generic
  Date: Thu Jul 14 21:40:25 2022 +0800
  3 files changed, 25 insertions(+), 19 deletions(-)
[arm_key_5.10.y fde64a36fa74] arm64: kexec_file: use more system keyrings to verify kernel image signature
  Date: Thu Jul 14 21:40:26 2022 +0800
  1 file changed, 1 insertion(+), 10 deletions(-)

On Mon, Aug 15, 2022 at 05:33:06PM +0200, gregkh@linuxfoundation.org wrote:
>
>The patch below does not apply to the 5.10-stable tree.
>If someone wants it applied there, or to any other stable or longterm
>tree, then please email the backport, including the original git commit
>id to <stable@vger.kernel.org>.
>
>thanks,
>
>greg k-h
>
>------------------ original commit in Linus's tree ------------------
>
>From 0d519cadf75184a24313568e7f489a7fc9b1be3b Mon Sep 17 00:00:00 2001
>From: Coiby Xu <coxu@redhat.com>
>Date: Thu, 14 Jul 2022 21:40:26 +0800
>Subject: [PATCH] arm64: kexec_file: use more system keyrings to verify kernel
> image signature
>
>Currently, when loading a kernel image via the kexec_file_load() system
>call, arm64 can only use the .builtin_trusted_keys keyring to verify
>a signature whereas x86 can use three more keyrings i.e.
>.secondary_trusted_keys, .machine and .platform keyrings. For example,
>one resulting problem is kexec'ing a kernel image  would be rejected
>with the error "Lockdown: kexec: kexec of unsigned images is restricted;
>see man kernel_lockdown.7".
>
>This patch set enables arm64 to make use of the same keyrings as x86 to
>verify the signature kexec'ed kernel image.
>
>Fixes: 732b7b93d849 ("arm64: kexec_file: add kernel signature verification support")
>Cc: stable@vger.kernel.org # 105e10e2cf1c: kexec_file: drop weak attribute from functions
>Cc: stable@vger.kernel.org # 34d5960af253: kexec: clean up arch_kexec_kernel_verify_sig
>Cc: stable@vger.kernel.org # 83b7bb2d49ae: kexec, KEYS: make the code in bzImage64_verify_sig generic
>Acked-by: Baoquan He <bhe@redhat.com>
>Cc: kexec@lists.infradead.org
>Cc: keyrings@vger.kernel.org
>Cc: linux-security-module@vger.kernel.org
>Co-developed-by: Michal Suchanek <msuchanek@suse.de>
>Signed-off-by: Michal Suchanek <msuchanek@suse.de>
>Acked-by: Will Deacon <will@kernel.org>
>Signed-off-by: Coiby Xu <coxu@redhat.com>
>Signed-off-by: Mimi Zohar <zohar@linux.ibm.com>
>
>diff --git a/arch/arm64/kernel/kexec_image.c b/arch/arm64/kernel/kexec_image.c
>index 9ec34690e255..5ed6a585f21f 100644
>--- a/arch/arm64/kernel/kexec_image.c
>+++ b/arch/arm64/kernel/kexec_image.c
>@@ -14,7 +14,6 @@
> #include <linux/kexec.h>
> #include <linux/pe.h>
> #include <linux/string.h>
>-#include <linux/verification.h>
> #include <asm/byteorder.h>
> #include <asm/cpufeature.h>
> #include <asm/image.h>
>@@ -130,18 +129,10 @@ static void *image_load(struct kimage *image,
> 	return NULL;
> }
>
>-#ifdef CONFIG_KEXEC_IMAGE_VERIFY_SIG
>-static int image_verify_sig(const char *kernel, unsigned long kernel_len)
>-{
>-	return verify_pefile_signature(kernel, kernel_len, NULL,
>-				       VERIFYING_KEXEC_PE_SIGNATURE);
>-}
>-#endif
>-
> const struct kexec_file_ops kexec_image_ops = {
> 	.probe = image_probe,
> 	.load = image_load,
> #ifdef CONFIG_KEXEC_IMAGE_VERIFY_SIG
>-	.verify_sig = image_verify_sig,
>+	.verify_sig = kexec_kernel_verify_pe_sig,
> #endif
> };
>

-- 
Best regards,
Coiby


  reply	other threads:[~2022-08-18  4:21 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2022-08-15 15:33 FAILED: patch "[PATCH] arm64: kexec_file: use more system keyrings to verify kernel" failed to apply to 5.10-stable tree gregkh
2022-08-18  4:15 ` Coiby Xu [this message]
2022-08-19 14:44   ` Greg KH
2022-08-19 14:48     ` Greg KH

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20220818041536.5urxrunzmdawkdh7@Rk \
    --to=coxu@redhat.com \
    --cc=bhe@redhat.com \
    --cc=gregkh@linuxfoundation.org \
    --cc=msuchanek@suse.de \
    --cc=stable@vger.kernel.org \
    --cc=will@kernel.org \
    --cc=zohar@linux.ibm.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox